CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point VPN-1 Edge Appliances
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-11-06
Junior Member
 
Join Date: 2008-10-28
Posts: 3
Rep Power: 0
JimHuddle has an average reputation (10+)
Default Setting an Edge device on the internal network

Hi folks,

I'm not quite a newb but managing CP is not my primary job so please bear with me.

Here's what I have:

Splat (intel) box at R65. (This is our Internet facing firewall.)
Edge device at firmware 7.0.42.

Here's what I want to accomplish:

We have several departments that constantly have vendors in to give dog and pony shows. These vendors usually need to connect to the Internet in some way. We don't allow non County equipment to attach to our wire for any reason. The philosophy is that if we don't control it, it doesn't connect.

Given that, in order to make our users happy we have considering putting in APs connected to Edge devices. The "foreigners" would then use wireless to do their thing. We'd like to establish a site to site VPN between the Edge and our Splat box at the network edge as the optimum choice. That way all non-County traffic would be inside a tunnel and completely away from our internal network. Protection in reverse, so to speak. If that isn't possible then we were thinking of just having the Edge route to the Splat box for all traffic from it's internal subnet and creating rules to drop any traffic from the Edge's internal subnet to our internal networks.

Here's what I tried:

I've been testing a site to site connection but can't seem to get it to work. It only will peer with the Splat box'es external interface and won't pass traffic from it's internal subnet. I've tried this with the Edge having the WAN address on the local subnet and also on a subnet outside the protected subs with the same result. Is there some documentation I can use to get this to work? Shouldn't the VPN peering be between the Splat box'es internal interface and the Edge? If so, what do I need to do to get it there?

I've also tried just using the Edge in router mode. In that mode I can't seem to connect to the Management server. Tracker is telling me there is a spoofing error and, of course, dropping the packets.

Another strange thing I've noticed is that if the Edge has an internal subnet's address (from our internal network) on the WAN port then hosts on that subnet begin to fall off from ping scans and I start getting duplicate address errors from hosts on that subnet. I've no clue how I'm managing to do that. This happens either trying to set up the VPN or just as a router.

I'd appreciate any help on this folks.

Thanks.

Jim
Reply With Quote
  #2 (permalink)  
Old 2008-11-06
Senior Member
 
Join Date: 2008-07-31
Location: Netherlands, Europe
Posts: 307
Rep Power: 1
msjouw has an average reputation (10+)
Default Re: Setting an Edge device on the internal network

When you want to connect the edge on the internal network and want to tunnel the world through the tunnel you need to setup a star topology (simplified VPN method) and tell it to route ALL traffic through the center and out to the internet.
Just add a rule to allow the edge lan to go to the any except the internal ranges, however whatch out with exclusion groups, they might not work on edges.
Give the edge WAN port a fixed IP and thenalso make sure the edge can do proper dns lookups.

On the edge, once it is connected to the R65, see what the https://x.x.x.x:981/vpntopo.html shows as the vpn topology. (x.x.x.x is WAN IP, make sure setup - management allows this)
It should route all traffic to the main firewall.
I would also see if you can upgrade to at least 7.0.47 or even 7.5.x just be aware you will also need to update the LIBSW on the SmartCenter.
__________________
Regards, Maarten.
P1 R62 IPSO SPLAT IOS

Last edited by msjouw; 2008-11-06 at 15:58.
Reply With Quote
  #3 (permalink)  
Old 2008-11-06
Junior Member
 
Join Date: 2008-10-28
Posts: 3
Rep Power: 0
JimHuddle has an average reputation (10+)
Default Re: Setting an Edge device on the internal network

Thanks Maarten,

I'll try that in the morning.

Jim
Reply With Quote
  #4 (permalink)  
Old 2008-11-07
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 267
Rep Power: 2
dantro has an average reputation (10+)
Default Re: Setting an Edge device on the internal network

1. do a firmware upgrade to 7.5.55x, which is the latest GA (recommendation due to a memory leak in that firmware: try to get 7.5.56x or 7.5.57x or even the new 8.x beta firmwares)
2. update the libsw files on your SmartCenter Server
3. use multiple Edges with wireless functionality and create a WDS network with roaming
4. connect one Edge to your ISP router so that is has internet access
5. share the internet conection of that Edge with all other Edges
6. read the UTM-1 Edges FAQ I wrote
7. get a support company that has in-depth knowledge to work with such Edge environments

This way your vendors won't even have to be tunneled through your existing network environment.

Last edited by dantro; 2008-11-07 at 03:57.
Reply With Quote
  #5 (permalink)  
Old 2008-11-07
Junior Member
 
Join Date: 2008-10-28
Posts: 3
Rep Power: 0
JimHuddle has an average reputation (10+)
Default Re: Setting an Edge device on the internal network

Thanks dantro,

Where might I find your FAQ?

Jim
Reply With Quote
  #6 (permalink)  
Old 2008-11-07
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 267
Rep Power: 2
dantro has an average reputation (10+)
Default Re: Setting an Edge device on the internal network

My FAQ can be found here.

What you want looks like this:



To set this up in a centralized environment you need some years of training. Just ask if you need support.
Reply With Quote
  #7 (permalink)  
Old 2008-11-07
Senior Member
 
Join Date: 2007-07-16
Posts: 687
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: Setting an Edge device on the internal network

Nice pic dantro!

One thing about this - does WDS support WPA yet? Last time I looked at this, you could only set WEP or no encryption on the WDS devices, and this is not a good security compromise generally...
Reply With Quote
  #8 (permalink)  
Old 2008-11-07
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 267
Rep Power: 2
dantro has an average reputation (10+)
Default Re: Setting an Edge device on the internal network

The internal 802.1x and WPA Authenticator provide Wi-Fi protected access via WPA or WPA2. That also works for WDS networks as you bind the WDS bridge directly to the WLAN interface.
Reply With Quote
  #9 (permalink)  
Old 2008-11-07
Senior Member
 
Join Date: 2007-07-16
Posts: 687
Rep Power: 2
Thorpuse has an average reputation (10+)
Default Re: Setting an Edge device on the internal network

Ahhh, now that's cool... have you tested this to ensure that connections aren't dropped when you roam between APs? Or will your connections drop when you move to the next AP?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 01:19.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0